Skip to content
feed: live
>_ 0dayNews
CVE Record
[ HIGH ] CVE-2026-68820

Windows AFD WinSock Use-After-Free Privilege Escalation

Use-after-free in Windows Ancillary Function Driver for WinSock (afd.sys) lets local attackers gain SYSTEM privileges via race condition. Actively exploited by Lazarus.

cat cve-2026-68820.json
Vendor
Microsoft
Product
Windows (multiple versions)
CVSS
7.0
EPSS (exploit probability)
N/A
Status
kev
Published

CVE-2026-68820 is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys), the kernel-mode driver that backs Windows socket operations. An authorized local attacker can trigger a race condition that corrupts freed memory, leading to SYSTEM privilege escalation.

Microsoft patched this in the August 2026 Patch Tuesday release. BleepingComputer reports that North Korea’s Lazarus group deployed the FudModule rootkit using this vulnerability before the patch was available — making it a confirmed zero-day exploitation in targeted campaigns.

Affected products: Windows (all actively supported versions as of August 2026 Patch Tuesday).

Mitigation: Apply the August 2026 Patch Tuesday cumulative update. No viable workaround exists for this class of kernel driver flaw; patching is the only remediation.

Priority: Immediate — active exploitation confirmed.